Skip to main content

Development trial ยท sample information only

Create and maintain a RoPA record

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Describe one processing activity, connect its data and people, and make gaps visible for review. RoPA means Record of Processing Activities.

Before you start

Speak to the people who run the activity. Gather its purpose, team, data inputs and outputs, affected people, recipients, retention and safeguards. Obtain the responsible privacy owner's conclusions where legal judgement is needed.

Describe a real activity, such as handling recruitment applications, rather than naming an entire department without a clear processing scope.

Create the record

  1. Open the RoPA catalogue and choose its create action.
  2. In Create New RoPA Entry, enter the activity name, Team and purpose.
  3. Select the applicable legal basis, processing type and organisation role from the available choices. Record the agreed basis; do not select an answer merely to fill a required field.
  4. Link relevant Business Capabilities, Source Data Entities, Output Data Entities and Data Subjects.
  5. Record retention and the actual facts about international transfers, processors and special-category data. Where transfer fields appear, use the verified destination and safeguard information.
  6. Describe the security measures and select Create RoPA.

Complete the working record

Open Narrative to explain how the activity operates in plain language. Review Data flow and relationships against the actual process; linked records should describe the same activity.

In Legal Compliance, inspect legal basis, retention, notices and rights coverage. The interface can show inherited rights and an Override for this activity action. Make an override only for an approved, recorded reason.

Review linked assessments, controls, risks and documentation. Use the overview's Readiness breakdown to find incomplete evidence, following each issue to its owning area.

Check it worked

Reload the record and ask the process owner to read it. They should recognise the actual inputs, outputs, people and systems. Confirm that links open the intended records and that remaining gaps are explicitly assigned.

The evidence export can help a reviewer inspect the current record. Exporting it does not complete an approval or prove compliance.

If something goes wrong

Problem Next action
A data category or subject is missing Create or correct the reusable data record, then link it
Readiness remains blocked Read the specific check; a complete narrative may still lack a required relationship
Inherited rights seem inappropriate Ask the privacy owner to review the source default before overriding it
The activity changes materially Update the source facts and revisit connected assessments and reviews

Human judgement matters

Backstory organises the evidence; it does not choose a lawful basis or validate a processing purpose for you.

What next?

For the wider context, see Manage privacy records and assessments.

Schedule a review and complete any required assessment. Keep the record current when the activity changes rather than waiting for an annual date.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?